Handoff in ad-hoc mobile broadband networks

ABSTRACT

A server is configured to maintain a session with a mobile client through a first mobile service provider. The server is further configured to pre-authenticate a second mobile service provider for handoff. The server is also configured to enable the handoff of the mobile client from the first mobile service provider to the second mobile service provider while maintaining the session with the mobile client.

CROSS-REFERENCE TO RELATED APPLICATION

The present application for patent claims priority under 35 U.S.C. §119 to Provisional Application No. 60/956,658 entitled, “Method For A Heterogeneous Wireless Ad Hoc Mobile Service Provider,” filed Aug. 17, 2007 and Provisional Application No. 60/980,557 entitled, “Handoff In Ad-Hoc Mobile Broadband Exchange,” filed Oct. 17, 2007.

BACKGROUND

1. Field

The present disclosure relates generally to telecommunications, and more specifically to handoff in an ad-hoc mobile broadband network.

2. Background

Wireless telecommunication systems are widely deployed to provide various services to consumers, such as telephony, data, video, audio, messaging, broadcasts, etc. These systems continue to evolve as market forces drive wireless telecommunications to new heights. Today, wireless networks are providing broadband Internet access to mobile subscribers over a regional, a nationwide, or even a global region. Such networks are sometimes referred to as Wireless Wide Area Networks (WWANs). WWAN operators generally offer wireless access plans to their subscribers such as subscription plans at a monthly fixed rate.

Accessing WWANs from all mobile devices may not be possible. Some mobile devices may not have a WWAN radio. Other mobile devices with a WWAN radio may not have a subscription plan enabled. Ad-hoc networking allows mobile devices to dynamically connect over wireless interfaces using protocols such as WLAN, Bluetooth, UWB or other protocols. There is a need in the art for a methodology to allow a user of a mobile device without WWAN access to dynamically subscribe to wireless access service provided by a user with a WWAN-capable mobile device using wireless ad-hoc networking between the mobile devices belong to the two users.

SUMMARY

In one aspect of the disclosure, a server includes a processing system configured to maintain a session with a mobile client through a first mobile service provider. The processing system is further configured to authenticate a second mobile service provider for handoff. The processing system is also configured to enable the handoff of the mobile client from the first mobile service provider to the second mobile service provider while maintaining the session with the mobile client.

In another aspect of the disclosure, a server includes means for maintaining a session with a mobile client through a first mobile service provider, means for pre-authenticating a second mobile service provider for handoff, and means for enabling the handoff of the mobile client from the first mobile service provider to the second mobile service provider while maintaining the session with the mobile client.

In a further aspect of the disclosure, a method of providing service from a server includes maintaining a session with a mobile client through a first mobile service provider. The method further includes pre-authenticating a second mobile service provider for handoff, and enabling the handoff of the mobile client from the first mobile service provider to the second mobile service provider while maintaining the session with the mobile client.

Inside yet a further aspect of the disclosure, machine-readable medium includes instructions executable by a processing system in a server. The instructions include code for maintaining a session with a mobile client through a first mobile service provider. The instructions further include code for pre-authenticating a second mobile service provider for handoff, and enabling the handoff of the mobile client from the first mobile service provider to the second mobile service provider while maintaining the session with the mobile client.

It is understood that other embodiments of the present invention will become readily apparent to those skilled in the art from the following detailed description, wherein various embodiments of the invention are shown and described by way of illustration. As will be realized, the invention is capable of other and different embodiments and its several details are capable of modification in various other respects, all without departing from the spirit and scope of the present invention. Accordingly, the drawings and detailed description are to be regarded as illustrative in nature and not as restrictive.

BRIEF DESCRIPTION OF THE DRAWINGS

FIG. 1 is a simplified block diagram illustrating an example of a telecommunications system.

FIG. 2 is a simplified block diagram illustrating an example of a handoff in a telecommunications system.

FIG. 3 is a call flow diagram illustrating an example of a pre-authentication process for handoff.

FIG. 4 is a simplified block diagram illustrating an example of a hardware configuration for a server.

FIG. 5 is a simplified block diagram illustrating an example of a hardware configuration for a processing system in a server.

FIG. 6 is a simplified block diagram illustrating an example of the functionality of a mobile service provider.

DETAILED DESCRIPTION

The detailed description set forth below in connection with the appended drawings is intended as a description of various configurations of the present invention and is not intended to represent the only configurations in which the present invention may be practiced. The detailed description includes specific details for the purpose of providing a thorough understanding of the present invention. However, it will be apparent to those skilled in the art that the present invention may be practiced without these specific details. In some instances, well-known structures and components are shown in block diagram form in order to avoid obscuring the concepts of the present invention.

FIG. 1 is a simplified block diagram illustrating an example of a telecommunications system. The telecommunications system 100 is shown with multiple WWANs that provide broadband access to a network 102 for mobile subscribers. The network 102 may be a packet-based network such as the Internet or some other suitable network. For clarity of presentation, two WWANs 104 are shown with a backhaul connection to the Internet 102. Each WWAN 104 may be implemented with multiple fixed-site base stations (not shown) dispersed throughout a geographic region. The geographic region may be generally subdivided into smaller regions known as cells. Each base station may be configured to serve all mobile subscribers within its respective cell. A base station controller (not shown) may be used to manage and coordinate the base stations in the WWAN 104 and support the backhaul connection to the Internet 102.

Each WWAN 104 may use one of many different wireless access protocols to support radio communications with mobile subscribers. By way of example, one WWAN 104 may support Evolution-Data Optimized (EV-DO), while the other WWAN 104 may support Ultra Mobile Broadband (UMB). EV-DO and UMB are air interface standards promulgated by the 3rd Generation Partnership Project 2 (3GPP2) as part of the CDMA2000 family of standards and employs multiple access techniques such as Code Division Multiple Access (CDMA) to provide broadband Internet access to mobile subscribers. Alternatively, one of WWAN 104 may support Long Term Evolution (LTE), which is a project within the 3GPP2 to improve the Universal Mobile Telecommunications System (UMTS) mobile phone standard based primarily on a Wideband CDMA (W-CDMA) air interface. One of WWAN 104 may also support the WiMAX standard being developed by the WiMAX forum. The actual wireless access protocol employed by a WWAN for any particular telecommunications system will depend on the specific application and the overall design constraints imposed on the system. The various techniques presented throughout this disclosure are equally applicable to any combination of heterogeneous or homogeneous WWANs regardless of the wireless access protocols utilized.

Each WWAN 104 has a number of mobile subscribers. Each subscriber may have a mobile node 106 capable of accessing the Internet 102 directly through the WWAN 104. In the telecommunications system shown in FIG. 1, these mobile nodes 106 access the WWAN 104 using an EV-DO, UMB or LTE wireless access protocol; however, in actual implementations, these mobile nodes 106 may be configured to support any wireless access protocol.

One or more of these mobile nodes 106 may be configured to create in its vicinity an ad-hoc network based on the same or different wireless access protocol used to access the WWAN 104. By way of example, a mobile node 106 may support a UMB wireless access protocol with a WWAN, while providing an IEEE 802.11 access point for mobile nodes 108 that cannot directly access a WWAN. IEEE 802.11 denotes a set of Wireless Local Access Network (WLAN) standards developed by the IEEE 802.11 committee for short-range communications (e.g., tens of meters to a few hundred meters). Although IEEE 802.11 is a common WLAN wireless access protocol, other suitable protocols may be used.

A mobile node 106 that may be used to provide an access point for another mobile node 108 will be referred to herein as a “mobile service provider.” A mobile node 108 that may use an access point of a mobile service provider 106 will be referred to herein as a “mobile client.” A mobile node, whether a mobile service provider 106 or a mobile client 108, may be a laptop computer, a mobile telephone, a personal digital assistant (PDA), a mobile digital audio player, a mobile game console, a digital camera, a digital camcorder, a mobile audio device, a mobile video device, a mobile multimedia device, or any other device capable of supporting at least one wireless access protocol.

The mobile service provider 106 may extend its wireless broadband Internet access service to mobile clients 108 that would otherwise not have Internet access. A server 110 may be used as an “exchange” to enable mobile clients 108 to purchase unused bandwidth from mobile service providers 106 to access, for example, the Internet 102 across WWANs 104.

A mobile service provider 106, a server 110, and one or more mobile clients 108 may establish a network that is an ad-hoc heterogeneous wireless network. By way of example, a heterogeneous wireless network may include at least two types of wireless networks (e.g., a WWAN and a WLAN). By way of example, an ad-hoc network may be a network whose specific configuration may change from time to time or from the formation of one network to the next. The network configuration is not pre-planned prior to establishing the network. Examples of configurations for an ad-hoc network may include a configuration as to which members are to be in the network (e.g., which mobile service provider, which server, and/or which mobile client(s) are to be included in a network), a configuration as to the geographic locations of a mobile service provider and mobile client(s), and a configuration as to when and how long a network is to be established.

In one example of an exchange, mobile clients 108 register with the server 110. Once registered, a mobile client 108 may search for available mobile service providers 106 when Internet access is desired. When the mobile client 108 detects the presence of one or more mobile service providers 106, it may select a mobile service provider 106 to initiate a session with based on various parameters such as bandwidth, Quality of Service (QoS) and cost. Another parameter that may be used by the mobile client 108 to select a mobile service provider 106 is availability in terms of time. By way of example, a mobile subscriber in an airport may turn on his mobile node (e.g., a laptop computer or a mobile telephone) and use it as a mobile service provider 108 for 30 minutes as he awaits his flight. A mobile client 108 requiring access to the Internet 102 for 45 minutes may choose not to select this mobile service provider 106 even if the mobile service provider 108 can provide adequate bandwidth with good QoS. Another mobile client 108, however, requiring Internet access for 15 minutes, may select this mobile service provider 106 because of its bandwidth and QoS. In any event, once a mobile client 108 selects a mobile service provider 106, a session may be established based on the parameters negotiated be the two (e.g., bandwidth, QoS, duration of the session, etc.). A link encryption key may be established between the mobile client 108 and the mobile service provider 106 during the establishment of the session. A Secured Socket Layer Virtual Private Network (SSL VPN) session may be established between the mobile client 108 and the server 110. The transport layer ports may be kept in the open and not encrypted to provide visibility for the network address translation functionality at the mobile service provider 106. In this example, all Internet traffic is routed through the server 110 via a client-server tunnel 112 to provide security.

In some telecommunication systems, once a mobile client 108 has gained access to the Internet 102, it listens for other mobile service providers 106 and measures the signal strength of the mobile service providers 106 it can hear. The mobile client 108 uses these measurements to create an active list. The active list is a list of mobile service providers 106 that can provide service to the mobile client 108. The mobile client 108 will continue to measure the signal strength of other mobile service providers 106 and may add or remove mobile service providers 106 from the active list as the configuration of the ad-hoc network changes.

One function of the active set is to allow the mobile client 108 to quickly switch between mobile service providers 106 while maintaining the current session with the server 110. The mobile client 108 may consider a handoff to another mobile service provider 106 based on any number of factors. These factors may include, by way of example, the inability of the mobile service provider 106 to provide the bandwidth or QoS negotiated at the beginning of the session. Alternatively, the mobile service provider 106 may not be able to provide Internet access to the mobile client 108 for the entire duration of the session. It would not be uncommon for a mobile subscriber on a mobile service provider 106 that negotiates a 30 minute session with a mobile client 108 to leave the vicinity 15 minutes into the session for whatever reason. In that event, the mobile client 108 would need to select a new mobile service provider from the active list for handoff. The server 110 uses the active list to pre-authenticate other mobile service providers for handoff during the session between the mobile client 108 and the current mobile service provider 106. By pre-authenticating the mobile service provider 106 in the active list before the mobile service provider 106 currently serving the mobile client 108 goes down, the time required to handoff the mobile client 108 can be reduced.

The term “pre-authenticating” as used herein means authenticating a target mobile service 106 provider for handoff prior to receiving a message from the mobile service provider 106 currently serving the mobile client 108 relating to the unavailability of the current mobile service provider 106. The message may provide notification to the server 110 that the current mobile service provider 106 has gone down and a hard handoff must be performed to another mobile service provider 106 if the session between the mobile client 108 and the server 110 is to be maintained. Alternatively, the message may provide notification to the server 110 that the current mobile service provider 106 will be going down shortly, or that it can no longer provide the mobile client 108 with the service agreed upon (e.g., QoS, bandwidth, etc.). This provides the server 110 with the option of enabling a soft handoff of the mobile client 108 to another mobile service provider 106.

Pre-authentication includes provisioning, prior to handoff, a potential new service provider 106 and a mobile client 108 with encryption/decryption keys that may be needed for communication between the potential new service provider 106 and the mobile client 108.

Pre-authentication also includes provisioning, prior to handoff, the current service provider 106 and the new service provider 106 with encryption/decryption keys that may be needed for communication between the current service provider 106 and the new service provider 106.

Pre-authentication also includes authorization of communication between the potential new service provider 106 and the current service provider 106. It also includes authorization of communication between the potential new service provider 106 and the mobile client 108.

FIG. 2 is a simplified block diagram illustrating an example of a handoff in a telecommunications system. In this example, the mobile client 108 is being handed off from a current mobile service provider 106 ₁ to a target service provider 106 ₂. A persistent tunnel 112 between the two mobile service providers 106 ₁, 106 ₂ is used to maintain the mobile client's session with the server 110 during handoff. Data packets received by the current mobile service provider 106 ₁ during handoff may be forwarded to the target mobile service provider 106 ₂ through the tunnel 112. Alternatively, or in addition to, the data packets received by the current service provider 106 ₁ may be forwarded to the target mobile service provider 106 ₂ directly over a wireless link 114 between the two as shown in FIG. 2, or through another mobile service provider (not shown).

The mobile client 108 may have an IPv4, IPv6, or other suitable address that is used by the server 110 to maintain the session. The address may be provided to the mobile client 108 by the server 110 or one of the mobile service providers 106 in the telecommunications network 100 (see FIG. 1). Alternatively, the address may be stored on the mobile client 108. In at least one configuration, the address may be a MobileIP address.

The tunneling anchor is shown in FIG. 2 as a server. However, the tunneling anchor may be any suitable entity or distributed across multiple entities in the telecommunications system 100. The tunneling anchor may be coupled to the Internet 102 as shown in FIG. 2 or located elsewhere. By way of example, the tunneling anchor may be located anywhere on the Internet 102 or within the network operator's infrastructure. Those skilled in the art will be readily able to determine the optimal implementation of the tunneling anchor for any particular application based on the performance requirements, the overall design constraints imposed on the system, and/or other relevant factors.

FIG. 3 is a call flow diagram illustrating an example of the authentication process for handoff. For clarity of presentation, various signaling for the mobile service providers 106 and clients 108 to authenticate the server 110 and register with the server 110 will be omitted.

In step 302, a connection may be initiated by a mobile service provider 106 ₁ with the server 110 when the mobile service provider 106 ₁ is mobile and desires to provide service. Extensible Authentication Protocol-Tunneled Transport Layer Security (EAP-TTLS) may be used for Authentication, Authorization and Accounting (AAA) and secure session establishment for this connection. In step 304, a connection may be initiated by a mobile client 108 with the mobile service provider 106 ₁ (hereinafter referred to as the “current mobile service provider”) when the mobile client 108 requires Internet access. EAP-TTLS may also be used for AAA and secure session establishment. In particular, the mobile service provider 106 ₁ sends the mobile client's credentials to the server 110 for EAP-AAA authentication. The EAP-TTLS authentication response from the server 110 is then used to generate a master shared key. Subsequently, a link encryption key may be established between the current mobile service provider 106 ₁ and the mobile client 108. A SSL VPN session may then be established, in step 306, between the mobile client 108 and the server 110.

It should be noted that information flow may be encrypted using encryption/decryption keys between any pair of nodes (where the nodes comprise the server 110, the current service provider 106 ₁, the target service provider 106 ₂, and the mobile client 108). Such encryption/decryption keys can be set up in the system when nodes in the system connect with the server. Typically symmetric key cryptography such as using AES may be used for such encryption or decryption for message-flow between any pair of nodes in the system.

In step 308, the mobile client 108 provides the active list to the server 110. Alternatively, the mobile client 108 can send a report identifying mobile service providers that it can hear accompanied by data indicating the signal strength measurements for each. The server 110 may use the report to generate the active list at its end.

The server 110 pre-authenticates one or more of the mobile service providers in the active list. During pre-authentication of a target service provider 106 ₂ with a client 108, the server 110 provisions the target-service provider 106 ₂ with an encryption/decryption key for communication with the client 108. The server may additionally provision the target service provider 106 ₂ with an encryption/decryption key for communication with the current service provider 106 ₁. The server 110 also provisions the client 108 with the encryption/decryption key to communicate with the target service provider 106 ₂. The current service provider 106 ₁ can be provisioned by the server 110, either at the time of a handoff or anytime earlier, with the encryption/decryption key to communicate with the target service provider 106 ₂. The exact number of mobile service providers in the active list that are pre-authenticated may depend on the admission control policies implemented by the server 110. By way of example, the server 110 may limit the number of mobile service providers at a given location if it determines that additional mobile service providers will adversely affect performance in the WWAN. Additional constraints may be imposed by the WWAN operators that may not want its mobile subscribers to provide service in a given geographic location depending on various network constraints. In any event, the server 110 pre-authenticates one or more mobile service providers by providing each of them with a key to encrypt the data link between the mobile client 108 and the new mobile service provider 106 following handoff. In FIG. 3, the server 110 is shown, in step 310, providing the key to one mobile service provider 106 ₂ (hereinafter referred to as the target mobile service provider). In step 312, the server 110 also provides the key to the mobile client 108 through the VPN tunnel.

In step 314, the mobile client 108 sends a message to the current mobile service provider 106 requesting a handoff to an alternate service provider. Step 314 is optional and is indicated by a dotted line from the client to the mobile service provider.

In step 316, the current mobile service provider 106, sends a message to the server 110 requesting a handoff. Such a message is tagged with an identifier that indicates that the handoff was initiated by the mobile client 108, or that it was initiated by the current mobile service provider 106 ₁. The message may be created at the current mobile service provider 106 ₁ as a consequence of the current mobile service provider's unavailability to continue to provide service to the mobile client. Alternatively, the message could have been created at the mobile client (step 314), which needs to be sent by the current mobile service provider 106, to the server 110. For a handoff that is initiated directly by the server, step 316 is optional. For a handoff that is initiated by the mobile client 108, or by the mobile service provider 106 ₁, in step 318, the server 110 responds to step 316 by sending a message back to current mobile service provider 106 ₁ authorizing handoff. Alternatively, step 318 could be a message from the server initiating a handoff, in the absence of a message 316 from the current mobile service provider 106 ₁. The message sent to the current mobile service provider 106 ₁ may identify the target mobile service provider 106 ₂ for handoff, or alternatively, allow the mobile client 108 to make the decision. In the latter case, the user on the mobile client 108 selects a target mobile service provider for handoff in accordance with any admission control policy constraints imposed by the server 110. The server 110 may also provide the mobile client 108 with a quality metric for each mobile service provider available to the mobile client. This quality metric may be used to assist the user on a mobile client 108 to select a new mobile service provider for handoff. In the example shown in FIG. 3, the mobile client 108 selects the target mobile service provider 106 ₂ for handoff.

In step 320, the server may optionally send a message regarding the handoff to one or more target service providers 106 ₂. In step 322, the handoff message received from the server 110 is sent by the current service provider 106, to the mobile client 108.

In step 324, the mobile client 108 establishes a connection with the target mobile service provider 106 ₂ by sending a message encrypted with a key. Since the target mobile service provider 106 ₂ received the same key during the pre-authentication process, it can decrypt the message and establish a session with the mobile client 108 to complete the handoff. The target mobile service provider 106 ₂ may also send a message back to the server 110, in step 326, to signify that the handoff has been successfully completed.

Packets that have left the mobile client 108 may be in transit to the current mobile service provider 106 ₁, or could be at the current mobile service provider 106 ₁. These packets need to continue to be supported by the current mobile service provider 106 ₁. Other packets that have left the mobile client 108 may be in transit to the server 110, or may be waiting at server 110 for further processing, or may be in transit to their final destination beyond the tunneling server. Future packets that leave the mobile client 108 are sent to the target mobile service provider 106 ₂ after handoff. Packets that are destined to the mobile client 108 may be waiting at the server. Such packets are sent to the target mobile service provider 106 ₂ after handoff. Other packets destined for the mobile client 108 may be in transit to the current mobile service provider 106 ₁, or may be waiting at the current mobile service provider 106 ₁, or may be in transit from the current service provider to the mobile client 108, and the current mobile service provider 106 ₁ needs to continue to support such packets to be delivered to the mobile client 108. The delivery of such packets can be done over a wireless link or a multi-hop wireless path between the current mobile service provider 106 ₁ and the target mobile service provider 106 ₂. Alternatively, such packets can be delivered by the current mobile service provider 106 ₁ to the server 110, which then sends them through the target mobile service provider 106 ₂. Messages between the current mobile service provider 106 ₁ and the target mobile service provider 106 ₂ may be exchanged either through the server 110, or over a wireless link or multi-hop wireless path between the service providers.

FIG. 4 illustrates an example of a hardware implementation for a server. The server 110 may be a centralized server or a distributed server. A centralized server may be a dedicated server or integrated into another network-related entity, such as a desktop or laptop computer, mainframe, or other suitable entity. A distributed server may be distributed across multiple servers and/or one or more network-related entities, such as a desktop or laptop computer, mainframe, or some other suitable entity. In at least one configuration, the server may be integrated, either in whole or part, into one or more mobile service providers.

The server 110 is shown with a network interface 402, which may support a wired and/or wireless connection to the Internet 102. The network interface 402 may be used to implement the physical layer by providing the means to transmit and receive data in accordance with the physical and electrical specifications required to interface to the transmission medium. The network 402 may also be configured to implement the lower portion of the data link layer by managing access to the transmission medium.

The server 110 is also shown with a processing system 404 that provides various functions, including session management for mobile service providers and clients, pre-authentication of mobile service providers targeted for handoff, handoff of mobile clients from one mobile service providers to another, and data tunneling for mobile clients. The processing system 404 is shown separate from the network interface 402, however, as those skilled in the art will readily appreciate, the network interface 402, or any portion thereof, may be integrated into the processing system 404.

FIG. 5 illustrates an example of a hardware implementation for a processing system in a server. In this example, the processing system 404 may be implemented with a bus architecture represented generally by bus 502. The bus 502 may include any number of interconnecting buses and bridges depending on the specific application of the processing system 404 and the overall design constraints. The bus links together various circuits including a processor 504 and machine-readable media 506. The bus 502 may also link various other circuits such as timing sources, peripherals, voltage regulators, power management circuits, and the like, which are well known in the art, and therefore, will not be described any further. A network adapter 508 provides an interface between the network interface 402 (see FIG. 4) and the bus 502.

The processor 504 is responsible for managing the bus and general processing, including the execution of software stored on the machine-readable media 506. The processor 504 may be implemented with one or more general-purpose and/or special-purpose processors. Examples include microprocessors, microcontrollers, DSP processors, and other circuitry that can execute software. Software shall be construed broadly to mean instructions, data, or any combination thereof, whether referred to as software, firmware, middleware, microcode, hardware description language, or otherwise. Machine-readable media may include, by way of example, RAM (Random Access Memory), flash memory, ROM (Read Only Memory), PROM (Programmable Read-Only Memory), EPROM (Erasable Programmable Read-Only Memory), EEPROM (Electrically Erasable Programmable Read-Only Memory), registers, magnetic disks, optical disks, hard drives, or any other suitable storage medium, or any combination thereof.

In the hardware implementation illustrated in FIG. 5, the machine-readable media 506 is shown as part of the processing system 404 separate from the processor 504. However, as those skilled in the art will readily appreciate, the machine-readable media 506, or any portion thereof, may be external to the processing system 404. By way of example, the machine-readable media 506 may include a transmission line, a carrier wave modulated by data, and/or a computer product separate from the server, all which may be accessed by the processor 504 through the network adapter 508. Alternatively, or in addition to, the machine readable media 506, or any portion thereof, may be integrated into the processor 504, such as the case may be with cache and/or general register files.

The processing system 404 may be configured as a general-purpose processing system with one or more microprocessors providing the processor functionality and external memory providing at least a portion of the machine-readable media 506, all linked together with other supporting circuitry through an external bus architecture. Alternatively, the processing system 404 may be implemented with an ASIC (Application Specific Integrated Circuit) with the processor 504, the network adapter 508, supporting circuitry (not shown), and at least a portion of the machine-readable media 506 integrated into a single chip, or with one or more FPGAs (Field Programmable Gate Array), PLDs (Programmable Logic Device), controllers, state machines, gated logic, discrete hardware components, or any other suitable circuitry, or any combination of circuits that can perform the various functionality described throughout this disclosure. Those skilled in the art will recognize how best to implement the described functionality for the processing system 404 depending on the particular application and the overall design constraints imposed on the overall system.

The machine-readable media 506 is shown with a number of software modules. The software modules include a protocol stack module 509, a pre-authentication module 510, a session manager module 512, a tunneling module 514, and a handoff module 516. These software modules include instruction sets that when executed by the processor 504 cause the processing system 402 to carry out the process steps as shown and described in FIGS. 1-3. Each software module may reside in a single storage device or distributed across multiple memory devices. By way of example, a software module may be loaded into RAM from a hard drive when a triggering event occurs (e.g., a mobile node decides to become a mobile service provider). During execution of the software module, the processor 504 may load some of the instructions into cache to increase access speed. One or more cache lines may then be loaded into a general register file for execution by the processor 504. When referring to the functionality of a software module below, it will be understood that such functionality is implemented by the processor 504 when executing instructions from that software module.

The protocol stack module 509 may be used to implement the protocol architecture, or any portion thereof, for the server. In the implementation described thus far, the protocol stack module 509 is responsible for implementing several protocol layers running on top of the data link layer implemented by the network interface 402 (see FIG. 4). By way of example, the protocol stack module 509 may be used to implement the upper portion of the data link layer by providing flow control, acknowledgement, and error recovery. The protocol stack module 509 may also be used to implement the network layer by managing source to destination data packet transfer, as well as the transport layer by providing transparent transfer of data between end users. Although described as part of the processing system, the protocol stack module 509, or any portion thereof, may be implemented by the network interface 402.

The session manager module 512 may be used by the server to maintain sessions with the mobile service providers and clients.

The pre-authentication module 510 may be used to pre-authenticate mobile service providers for handoff. The pre-authentication module 510 may receive from a mobile client a list of mobile service providers in the coverage region for the mobile client and use the list to identify the mobile service provider for pre-authentication.

The handoff module 516 may be used to enable the handoff of a mobile client between mobile service providers while the session manager module 512 maintains the session with the mobile client. The handoff module 516 may enable handoff by authenticating the mobile client for the target service provider prior to handoff and provisioning the target service provider and the mobile client with a key to support an encrypted link between the two following handoff. The handoff may be enabled in response to various messages, including by way of example, a message indicating that the mobile client has selected the target service provider, a message indicating the unavailability of the service provider currently serving the mobile client, or a request from the mobile client for a handoff. The handoff may be a hard or soft handoff. When the handoff is complete, an indication may be received by the handoff module 516. The handoff module 516 may further provide a method for forwarding packets received by the current service provider to the target service provider following handoff through a tunnel between the server and the target service provider, a wireless link, another mobile service provider, or by some other suitable means.

The tunneling module 514 may be used by the server to maintain tunnels with mobile service providers and clients. The tunneling module 514 may also be used to maintain a tunnel with a mobile client during handoff from a current mobile service provider to a target service provider. In the disclosed configuration, the tunneling is performed by a module in the server. However, in other configurations, the tunneling of data between the Internet and the nodes (i.e., mobile service providers and clients) may be located elsewhere in the network.

FIG. 6 is a simplified block diagram illustrating an example of the functionality of a mobile service provider. The mobile service provider 106 has the ability to bridge wireless links over homogeneous or heterogeneous wireless access protocols. This may be achieved with a WWAN network adapter 602 that supports a wireless access protocol for a WWAN to the Internet 102, and a WLAN network adapter 604 that provides a wireless access point for mobile clients 108. By way of example, the WWAN network adapter 602 may include a transceiver function that supports EV-DO for Internet access through a WWAN, and the WLAN network adapter 604 may include a transceiver function that provides an 802.11 access point for mobile clients 108. Each network adapter 602, 604 may be configured to implement the physical layer by demodulating wireless signals and performing other radio frequency (RF) front end processing. Each network adapter 602, 604 may also be configured to implement the data link layer by managing the transfer of data across the physical layer.

The mobile service provider 106 is shown with a filtered interconnection and session monitoring module 606. The module 606 provides filtered processing of content from mobile clients 108 so that the interconnection between the ad-hoc wireless links to the WWAN network interface 602 is provided only to mobile clients 108 authenticated and permitted by the server to use the WWAN network. The module 606 also maintains tunneled connectivity between the server and the authenticated mobile clients 108.

The mobile service provider 106 also includes a service provider application 608 that (1) enables the module 606 to provide ad-hoc services to mobile clients 108, and (2) supports WWAN or Internet access to a mobile subscriber or user of the mobile service provider 106. The latter function is supported by a user interface 612 that communicates with the WWAN network adapter 602 through the module 606 under control of the service provider application 608. The user interface 612 may include a keypad, display, speaker, microphone, joystick, and/or any other combination user interface devices that enable a mobile subscriber or user to access the WWAN 104 or the Internet 102 (see FIG. 1).

As discussed above, the service provider application 608 also enables the module 606 to provide ad-hoc services to mobile clients 108. The service provider application 608 maintains a session with the server 110 to exchange custom messages with the server. In addition, the service provider application 608 also maintains a separate session with each mobile client 108 for exchanging custom messages between the service provider application 608 and the mobile client 108. The service provider application 608 provides information on authenticated and permitted clients to the filtered interconnection and session monitoring module 606. The filtered interconnection and session monitoring module 608 allows content flow for only authenticated and permitted mobile clients 108. The filtered interconnection and session monitoring module 606 also optionally monitors information regarding content flow related to mobile clients 108 such as the amount of content outbound from the mobile clients and inbound to the mobile clients, and regarding WWAN and WLAN network resource utilization and available bandwidths on the wireless channels. The filtered interconnection and session monitoring module 606 can additionally and optionally provide such information to the service provider application 608. The service provider application 608 can optionally act on such information and take appropriate actions such as determining whether to continue maintaining connectivity with the mobile clients 108 and with the server, or whether to continue to provide service. It should be noted that the functions described in modules 606 and 608 can be implemented in any given platform in one or multiple sets of modules that coordinate to provide such functionality at the mobile service provider 106.

When the mobile service provider 106 decides to provide these services, the service provider application 608 sends a request to the server 110 for approval. The service provider application 608 requests authentication by the server 110 and approval from the server 110 to provide service to one or more mobile clients 108. The server 110 may authenticate the mobile service provider 106 and then determine whether it will grant the mobile service provider's request. As discussed earlier, the request may be denied if the number of mobile service providers in the same geographic location is too great or if the WWAN operator has imposed certain constraints on the mobile service provider 106.

Once the mobile service provider 106 is authenticated, the service provider application 608 may advertise an ad-hoc WLAN Service Set Identifier (SSID). Interested mobile clients 108 may associate with the SSID to access the mobile service provider 106. The service provider application 608 may then authenticate the mobile clients 108 with the server 110 and then configure the filtered interconnection and session monitoring module 606 to connect the mobile clients 108 to the server. During the authentication of a mobile client 108, the service provider application 608 may use an unsecured wireless link.

The service provider application 608 may optionally choose to move a mobile client 108 to a new SSID with a secure link once the mobile client 108 is authenticated. In such situations, the service provider application 608 may distribute the time it spends in each SSID depending on the load that it has to support for existing sessions with mobile clients 108.

The service provider application 608 may also be able to determine whether it can support a mobile client 108 before allowing the mobile client 108 to access a network. Resource intelligence that estimates the drain on the battery power and other processing resources that would occur by accepting a mobile client 108 may assist in determining whether the service provider application 608 should consider supporting a new mobile client 108 or accepting a handoff of that mobile client 108 from another mobile service provider 106.

The service provider application 608 may admit mobile clients 108 and provide them with a certain QoS guarantee, such as an expected average bandwidth during a session. Average throughputs provided to each mobile client 108 over a time window may be monitored. The service provider application 608 may monitor the throughputs for all flows going through it to ensure that resource utilization by the mobile clients 108 is below a certain threshold, and that it is meeting the QoS requirement that it has agreed to provide to the mobile clients 108 during the establishment of the session.

The service provider application 608 may also provide a certain level of security to the wireless access point by routing content through the filtered interconnection and session monitoring module 606 without being able to decipher the content. Similarly, the service provider application 608 may be configured to ensure content routed between the user interface 610 and the WWAN 104 via the module 606 cannot be deciphered by mobile clients 108. The service provider application 608 may use any suitable encryption technology to implement this functionality.

The service provider application 608 may also maintain a time period for a mobile client 108 to access a network. The time period may be agreed upon between the service provider application 608 and the mobile client 108 during the initiation of the session. If the service provider application 608 determines that it is unable to provide the mobile client 108 with access to the network for the agreed upon time period, then it may notify both the server and the mobile client 108 regarding its unavailability. This may occur due to energy constraints (e.g., a low battery), or other unforeseen events. The server may then consider a handoff of the mobile client to another mobile service provider, if there is such a mobile service provider in the vicinity of the mobile client 108. The service provider application 608 may support the handoff of the mobile client 108.

The service provider application 608 may also dedicate processing resources to maintain a wireless link or limited session with mobile clients 108 served by other mobile service providers. This may facilitate the handoff of mobile clients 108 to the mobile service provider 106.

The service provider application 608 may manage the mobile client 108 generally, and the session specifically, through the user interface 612. Alternatively, the service provider application 608 may support a seamless operation mode with processing resources being dedicated to servicing mobile clients 108. In this way, the mobile client 108 is managed in a way that is transparent to the mobile subscriber. The seamless operation mode may be desired where the mobile subscriber does not want to be managing mobile clients 108, but would like to continue generating revenue by sharing bandwidth with mobile clients 108.

Turning now to the mobile client, a TLS session may be used by the mobile client 108 to register with the server 110. Once registered, the mobile client 108 may search for available mobile service providers 106. When the mobile client 108 detects the presence of one or more mobile service providers 106, it may initiate a session using EAP-TTLS with a mobile service provider 106 based on parameters such as the available bandwidth that the mobile service provider 106 can support, the QoS metric of the mobile service provider 106, and the cost of the service advertised. As described earlier, a link encryption key may be established between the mobile client 108 and the mobile service provider 106 during the establishment of the session. An SSL VPN session may be established between the mobile client 108 and the server 110 so that all traffic between the two is encrypted. The transport layer ports may be kept in the open and not encrypted to provide visibility for the network address translation functionality at the mobile service provider 106.

The handoff of the mobile client 108 may be performed in a variety of ways. In one configuration, the mobile client 108 may maintain a limited session with multiple mobile service providers 106, while using one mobile service provider 106 to access the Internet. As described earlier, this approach may facilitate the handoff process. In an alternative configuration, the mobile client 108 may consider a handoff only when necessary. In this configuration, the mobile client 108 may maintain an active list of mobile service providers 106 in its vicinity for handoff. The mobile client 108 may select a mobile service provider 106 for handoff from the active list when the current mobile service provider 106 needs to discontinue its service. When handoff is not possible, a mobile client 108 may need to reconnect through a different mobile service provider 106 to access the Internet. Persistence of the tunnel between the mobile client and the server can enable a soft handoff of a mobile client from one service provider to another service provider.

If the bandwidth needs of a mobile client 108 are greater than the capabilities of the available mobile service providers 106, then the mobile client 108 may access multiple mobile service providers 106 simultaneously. A mobile client 108 with multiple transceivers could potentially access multiple mobile service providers 106 simultaneously using a different transceiver for each mobile service provider 106. If the same wireless access protocol can be used to access multiple mobile service providers 106, then different channels may be used. If the mobile client 108 has only one transceiver available, then it may distribute the time that it spends accessing each mobile service provider 106.

Those of skill in the art would appreciate that the various illustrative blocks, modules, elements, components, methods, and algorithms described herein may be implemented as electronic hardware, computer software, or combinations of both. To illustrate this interchangeability of hardware and software, various illustrative blocks, modules, elements, components, methods, and algorithms have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware or software depends upon the particular application and design constraints imposed on the overall system. Skilled artisans may implement the described functionality in varying ways for each particular application.

It is understood that the specific order or hierarchy of steps in the processes disclosed is an illustration of exemplary approaches. Based upon design preferences, it is understood that the specific order or hierarchy of steps in the processes may be rearranged. The accompanying method claims present elements of the various steps in a sample order, and are not meant to be limited to the specific order or hierarchy presented.

The previous description is provided to enable any person skilled in the art to practice the various aspects described herein. Various modifications to these aspects will be readily apparent to those skilled in the art, and the generic principles defined herein may be applied to other aspects. Thus, the claims are not intended to be limited to the aspects shown herein, but is to be accorded the full scope consistent with the language claims, wherein reference to an element in the singular is not intended to mean “one and only one” unless specifically so stated, but rather “one or more.” Unless specifically stated otherwise, the term “some” refers to one or more. Pronouns in the masculine (e.g., his) include the feminine and neuter gender (e.g., her and its) and vice versa. All structural and functional equivalents to the elements of the various aspects described throughout this disclosure that are known or later come to be known to those of ordinary skill in the art are expressly incorporated herein by reference and are intended to be encompassed by the claims. Moreover, nothing disclosed herein is intended to be dedicated to the public regardless of whether such disclosure is explicitly recited in the claims. No claim element is to be construed under the provisions of 35 U.S.C. §112, sixth paragraph, unless the element is expressly recited using the phrase “means for” or, in the case of a method claim, the element is recited using the phrase “step for.” 

1. A server, comprising: a processing system configured to maintain a session with a mobile client through a first mobile service provider, the processing system being further configured to pre-authenticate a second mobile service provider for handoff, and wherein the processing system is further configured to enable the handoff of the mobile client from the first mobile service provider to the second mobile service provider while maintaining the session with the mobile client.
 2. The server of claim 1 wherein the processing system is further configured to authenticate the mobile client for the second service provider prior to the handoff of the mobile client to the second service provider.
 3. The server of claim 1 wherein the processing system is further configured to provision the second service provider and the mobile client with a key to support an encrypted link between the mobile client and the second mobile service provider following the handoff.
 4. The server of claim 1 wherein the processing system is further configured to receive from the mobile client a list of mobile service providers in the coverage region for the mobile client, the processing system being further configured to use the list to identify the second mobile service provider for pre-authentication.
 5. The server of claim 1 wherein the processing system is further configured to enable the handoff in response to a message indicating that the mobile client has selected the second mobile service provider for the handoff.
 6. The server of claim 1 wherein the processing system is further configured to enable the handoff in response to a message relating to the unavailability of the first mobile service provider.
 7. The server of claim 1 wherein the processing system is further configured to enable the handoff in response to a message relating to a request from the mobile client for a handoff from the first mobile service provider to the second mobile service provider.
 8. The server of claim 1 wherein the processing system is further configured to initiate the handoff of the mobile client from the first mobile service provider to the second mobile service provider.
 9. The server of claim 1 wherein the processing system is further configured to enable the handoff by providing a request to the first mobile service provider to handoff the mobile client, the processing system being further configured to receive from the second mobile service provider an indication when the handoff is complete.
 10. The server of claim 1 wherein the processing system is further configured to support a tunnel with the mobile client.
 11. The server of claim 10 wherein the processing system is further to maintain the tunnel with the mobile client during the handoff of the mobile client from the first mobile service provider to the second mobile service provider.
 12. The server of claim 10 wherein the processing system is further configured to forward at least some packets received by the first mobile service provider from the mobile client through the tunnel to the second mobile service provider.
 13. The server of claim 1 which the processing system is further configured to support forwarding of at least some packets from the first mobile service provider to the second mobile service provider over a wireless link between the first and second service providers.
 14. The server of claim 13 wherein the processing system is further configured to support the forwarding of the packets from the first mobile service provider to the second mobile service provider through another mobile service provider.
 15. The server of claim 1 wherein the processing system is further configured to provide an IPv4 or IPv6 address to the mobile client.
 16. The server of claim 15 wherein the IPv4 or IPv6 address comprises a MobileIP address.
 17. The server of claim 1 wherein the handoff comprises a hard handoff.
 18. The server of claim 1 wherein the handoff comprises a soft handoff.
 19. A server, comprising: means for maintaining a session with a mobile client through a first mobile service provider; means for pre-authenticating a second mobile service provider for handoff; and means for enabling the handoff of the mobile client from the first mobile service provider to the second mobile service provider while maintaining the session with the mobile client.
 20. The server of claim 19 wherein the means for pre-authenticating the second mobile service provider comprises means for providing the second mobile service provider with a key to support an encrypted link between the mobile client and the second mobile service provider following the handoff.
 21. The server of claim 20 further comprising means for providing the key to the mobile client.
 22. The server of claim 19 further comprising means for receiving from the mobile client a list of mobile service providers in the coverage region for the mobile client and means for using the list to identify the second mobile service provider for pre-authentication.
 23. The server of claim 19 wherein the means for enabling the handoff comprises means for enabling the handoff in response to a message indicating that the mobile client has selected the second mobile service provider for the handoff.
 24. The server of claim 19 wherein the means for enabling the handoff comprises means for enabling the handoff in response to a message relating to the unavailability of the first mobile service provider.
 25. The server of claim 19 wherein the means for enabling the handoff comprises means for providing a request to the first mobile service provider to handoff the mobile client and means for receiving from the second mobile service provider an indication when the handoff is complete.
 26. The server of claim 19 wherein the means for maintaining a session with the mobile client further comprises means for supporting a tunnel with the mobile client.
 27. The server of claim 26 wherein the means for supporting the tunnel is configured to maintain the tunnel with the mobile client during the handoff of the mobile client from the first mobile service provider to the second mobile service provider.
 28. The server of claim 26 further comprising means for forwarding at least some packets received by the first mobile service provider from the mobile client through the tunnel to the second mobile service provider.
 29. The server of claim 19 means for maintaining a session with the mobile client further comprises means for supporting forwarding of at least some packets from the first mobile service provider to the second mobile service provider over a wireless link between the first and second service providers.
 30. The server of claim 29 wherein the means for supporting the forwarding of packets is configured to support the forwarding of the packets from the first mobile service provider to the second mobile service provider through another mobile service provider.
 31. The server of claim 19 further comprising means for providing an IPv4 or IPv6 address to the mobile client.
 32. The server of claim 31 wherein the IPv4 or IPv6 address comprises a MobileIP address.
 33. The server of claim 19 wherein the handoff comprises a hard handoff.
 34. The server of claim 19 wherein the handoff comprises a soft handoff.
 35. A method of providing service from a server, comprising: maintaining a session with a mobile client through a first mobile service provider; pre-authenticating second mobile service provider for handoff; and enabling the handoff of the mobile client from the first mobile service provider to the second mobile service provider while maintaining the session with the mobile client.
 36. The method of claim 35 wherein the second mobile service provider is pre-authenticated by providing the second mobile service provider with a key to support an encrypted link between the mobile client and the second mobile service provider following the handoff.
 37. The method of claim 36 further comprising providing the key to the mobile client.
 38. The method of claim 35 further comprising receiving from the mobile client a list of mobile service providers in the coverage region for the mobile client and using the list to identify the second mobile service provider for pre-authentication.
 39. The method of claim 35 wherein the handoff is enabled in response to a message indicating that the mobile client has selected the second mobile service provider for the handoff.
 40. The method of claim 35 wherein the handoff is enabled in response to a message relating to the unavailability of the first mobile service provider.
 41. The method of claim 35 wherein the handoff is enabled by providing a request to the first mobile service provider to handoff the mobile client and receiving from the second mobile service provider an indication when the handoff is complete.
 42. The method of claim 35 wherein the session is maintained by supporting a tunnel with the mobile client.
 43. The method of claim 42 wherein the tunnel with the mobile client is supported during the handoff of the mobile client from the first mobile service provider to the second mobile service provider.
 44. The method of claim 42 further comprising forwarding at least some packets received by the first mobile service provider from the mobile client through the tunnel to the second mobile service provider.
 45. The method of claim 35 further comprising supporting forwarding of at least some packets from the first mobile service provider to the second mobile service provider over a wireless link between the first and second service providers.
 46. The method of claim 45 wherein the forwarding of packets is supported by forwarding the packets from the first mobile service provider to the second mobile service provider through another mobile service provider.
 47. The method of claim 35 further comprising providing an IPv4 or IPv6 address to the mobile client.
 48. The method of claim 47 wherein the IPv4 or IPv6 address comprises a MobileIP address.
 49. The method of claim 35 wherein the handoff comprises a hard handoff.
 50. The method of claim 35 wherein the handoff comprises a soft handoff.
 51. A machine-readable medium comprising instructions executable by a processing system in a server, the instructions comprising code for: maintaining a session with a mobile client through a first mobile service provider; pre-authenticating a second mobile service provider for handoff; and enabling the handoff of the mobile client from the first mobile service provider to the second mobile service provider while maintaining the session with the mobile client.
 52. The machine-readable medium of claim 51 wherein the code for pre-authenticating the second mobile service provider is configured to provide the second mobile service provider with a key to support an encrypted link between the mobile client and the second mobile service provider following the handoff.
 53. The machine-readable medium of claim 52 wherein the instructions further comprise code for providing the key to the mobile client.
 54. The machine-readable medium of claim 51 wherein the instructions further comprise code for receiving from the mobile client a list of mobile service providers in the coverage region for the mobile client and using the list to identify the second mobile service provider for pre-authentication.
 55. The machine-readable medium of claim 51 wherein the code for enabling the handoff is configured to enable the handoff in response to a message indicating that the mobile client has selected the second mobile service provider for the handoff.
 56. The machine-readable medium of claim 51 wherein the code for enabling the handoff is configured to enable the handoff in response to a message relating to the unavailability of the first mobile service provider.
 57. The machine-readable medium of claim 51 wherein the code for enabling the handoff is configured to provide a request to the first mobile service provider to handoff the mobile client and receive from the second mobile service provider an indication when the handoff is complete.
 58. The machine-readable medium of claim 51 wherein the code for maintaining a session with the mobile client is configured to support a tunnel with the mobile client.
 59. The machine-readable medium of claim 58 wherein the code for maintaining a session is further configured to maintain the tunnel with the mobile client during the handoff of the mobile client from the first mobile service provider to the second mobile service provider.
 60. The machine-readable medium of claim 58 wherein the instructions further comprise code for forwarding at least some packets received by the first mobile service provider from the mobile client through the tunnel to the second mobile service provider.
 61. The machine-readable medium of claim 51 wherein the instructions further comprise code for supporting forwarding of at least some packets from the first mobile service provider to the second mobile service provider over a wireless link between the first and second service providers.
 62. The machine-readable medium of claim 61 wherein the code for supporting forwarding of packets is configured to support the forwarding of the packets from the first mobile service provider through the second mobile service provider through another mobile service provider.
 63. The machine-readable medium of claim 51 wherein the instructions further comprise code for providing an IPv4 or IPv6 address to the mobile client.
 64. The machine-readable medium of claim 63 wherein the IPv4 or IPv6 address comprises a MobileIP address.
 65. The machine-readable medium of claim 51 wherein the handoff comprises a hard handoff.
 66. The machine-readable medium of claim 51 wherein the handoff comprises a soft handoff. 